How can SQL injection be prevented when using user input in PHP code?
SQL injection can be prevented by using prepared statements with parameterized queries in PHP code. This approach ensures that user input is treated as data rather than executable SQL code, thereby preventing malicious SQL injection attacks.
// Establish a database connection
$pdo = new PDO("mysql:host=localhost;dbname=mydatabase", "username", "password");
// Prepare a SQL statement with a parameterized query
$stmt = $pdo->prepare("SELECT * FROM users WHERE username = :username");
// Bind the user input to the parameter
$stmt->bindParam(':username', $_POST['username']);
// Execute the query
$stmt->execute();
// Fetch the results
$results = $stmt->fetchAll();
Related Questions
- How can the "ORDER BY" and "LIMIT" clauses be used in PHP to retrieve the ID of the latest news entry from a database?
- What are the advantages and disadvantages of using XSL, DOM, and SimpleXML for HTML rendering on the server in PHP?
- What are common pitfalls for beginners in PHP when trying to automatically fill a shopping cart?